logo

Updated Cyber Threat Actor Naming System

ID: 273f1110-bae9-5a31-ba10-f3d8185a4334

STIX ID: report--273f1110-bae9-5a31-ba10-f3d8185a4334

Feed Name: Google Cloud Threat Intelligence

Date Published: 2026-07-24

Date Updated: 2026-07-24

Author: Google Threat Intelligence Group

...
...

GTIG announces a unified cryptonym-based naming convention for threat actors: a memorable two-word cryptonym where the first word uniquely identifies the actor (reusing prior names when available) and the second word categorizes motivation, attribution, or activity type (e.g., CASTLE for China, ION for Iran, NEPTUNE for North Korea, RELIC for Russia, COMET for cybercriminals). The release explains rationale, mapping examples, preservation of legacy aliases and MITRE ATT&CK mappings, and notes that renaming of the most active groups will roll out progressively.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.